Why combine both views
Source context can expose hidden assumptions and risky flows; runtime evidence shows whether the path is reachable in the configured environment.
- Candidate generation from code
- Targeted runtime checks
- Consolidated root-cause reporting
Inputs
An agreed repository revision, a reachable staging or approved production target, purpose-built test accounts, authorization evidence, and scope constraints.
- Least-privilege credentials
- Synthetic test data preferred
- Production-impact exclusions documented
Output and limits
Findings would pair code locations with observed requests and responses, while separating confirmed facts from model conclusions. Results remain point-in-time and do not certify the entire system.